driver.exe

2007 Microsoft Office system

PORT PROM

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable driver.exe, “2007 Microsoft Office component” has been detected as malware by 1 anti-virus scanner. This is a setup program which is used to install the application. The file has been seen being downloaded from wikiweb.com.ua.
Publisher:
Microsoft Corporation  (signed by PORT PROM)

Product:
2007 Microsoft Office system

Description:
2007 Microsoft Office component

Version:
12.0.6606.1000

MD5:
62f7a8778351d856a516c37f68c88955

SHA-1:
7d9ea45036a93a928ed1c2ff5d706a2bf1aadd02

SHA-256:
c0b14af20a1d2b5f28bd3f5ebef9b4cfa6b2be8d49091bbf74eaad870e48718b

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
5/11/2025 3:10:42 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.7.25.14

File size:
795.5 KB (814,568 bytes)

Product version:
12.0.6606.1000

Copyright:
© 2006 Microsoft Corporation. All rights reserved.

Original file name:
SetLang.Exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\driver.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/7/2016 6:00:00 AM

Valid to:
7/8/2017 5:59:59 AM

Subject:
CN=PORT PROM, O=PORT PROM, STREET="d. 33 str. 1, ul.1-Ya Brestskaya", L=Moscow, S=Moscow, PostalCode=125047, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00ED626D75C5323A188C6E74611FD410E9

File PE Metadata
Compilation timestamp:
7/21/2016 2:12:17 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:ndbLfIfz3kh9qxIhvkH1NEoD+STVoQMJX9Wx8AudzHNIoMWdr:dbU73wqxIh2TxVoQMWFudzHNIoMWdr

Entry address:
0x1000

Entry point:
55, 8B, EC, 81, EC, 64, 02, 00, 00, 53, 56, 57, C6, 85, 6F, FF, FF, FF, D6, 8D, 09, 68, 1D, 10, 40, 00, C3, CD, 7F, C7, 85, C0, FE, FF, FF, 29, 00, 00, 00, 81, BD, C0, FE, FF, FF, 06, A1, 00, 00, 76, 02, EB, 23, 8B, 85, C0, FE, FF, FF, 83, C0, 15, 89, 85, C0, FE, FF, FF, 68, 80, F0, 48, 00, FF, 15, 30, A2, 48, 00, B9, C3, 01, 00, 00, 85, C9, 75, CF, 8B, 95, B4, FE, FF, FF, 8B, 8D, D4, FE, FF, FF, D3, E2, 89, 95, D4, FE, FF, FF, A1, 34, 48, 4C, 00, 50, FF, 15, 34, A2, 48, 00, 8B, 8D, D4, FE, FF, FF, 2B, 8D...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
544.5 KB (557,568 bytes)

The file driver.exe has been seen being distributed by the following URL.

Remove driver.exe - Powered by Reason Core Security